BEA WebLogic Vulnerabilities and new updates

By N-Stalker Team on September 25, 2006

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
  • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 179)
  • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • CuteNews 1.4.1 Show_News.PHP Cross-Site Scripting Vulnerability
  • RunCMS 1.2 PMLite.PHP SQL Injection Vulnerability
  • V-webmail 1.6.2 Multiple Cross-Site Scripting Vulnerabilities
  • Gallery 1.5.2 Data Code Execution Vulnerability
  • MyBB 1.03 Managegroup.PHP Cross-Site Scripting Vulnerability
  • PHPNuke 7.7 Modules.PHP SQL Injection Vulnerability
  • MyBB 1.03 Managegroup.PHP SQL Injection Vulnerability
  • MyBB 1.03 Private.PHP Multiple SQL Injection Vulnerabilities
  • QwikiWiki 1.5 Search.PHP Cross-Site Scripting Vulnerability
  • CALimba 0.99.2 RB_auth.PHP Multiple SQL Injection Vulnerabilities
  • E107 Website System 0.6171 BBCode HTML Injection Vulnerability
  • sNews Multiple Input Validation Vulnerabilities
  • PHPNuke Header.PHP 7.8 Pagetitle Parameter Cross-Site Scripting Vulnerability
  • IPB Army System 2.1 Army.PHP SQL Injection Vulnerability
  • Clever Copy 2.0a Multiple HTML Injection Vulnerabilities
  • DocMGR 0.54.2 Process.PHP Remote File Include Vulnerability
  • XMB Forum 1.9.3 Multiple Input Validation Vulnerabilities
  • Lawrence Osiris DB_eSession Class 1.0.2 SQL Injection Vulnerability
  • PHP Event Calendar 1.5 HTML Injection Vulnerability
  • ELOG Web Logbook 2.6.1 Multiple Remote Vulnerabilities
  • ELOG 2.6.0 Web Logbook Multiple Remote Input Validation Vulnerabilities
  • Invision Power Board Portal Plugin 1.3 Index.PHP SQL Injection Vulnerability
  • Mantis 1.0 Config_Defaults_Inc.PHP Cross-Site Scripting Vulnerability
  • Webeveyn Whomp! Real Estate Manager Login SQL Injection Vulnerability
  • CRE Loaded 6.15 Files.PHP Access Validation Vulnerability
  • MyBB 1.02 Signature HTML Injection Vulnerability
  • CheesyBlog 1.0 Multiple HTML Injection Vulnerabilities
  • MyBB 1.0.2 Notepad UserCP.PHP HTML Injection Vulnerability
  • MiniGal MG2 0.5.1 Image Gallery Name Field HTML Injection Vulnerability
  • BEA WebLogic for Win32 8.1 SP5 Multiple Vulnerabilities
  • Zoph 0.4pre2 Unspecified SQL Injection Vulnerability
  • Pixelpost 1.4.3 User Comment HTML Injection Vulnerability
  • vBulletin 3.5.2 Showthread.PHP Input Validation Vulnerability
  • PHPBB 2.0.19 HTTP Referer Information Disclosure Vulnerability
  • OpenSSL 0.9.7j/0.9.8b RSA Signature Forgery Vulnerability

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.